CVE-2025-9521 | TP-Link Omada Controller up to 5.x Session Token insufficiently protected credentials
A vulnerability classified as problematic was found in TP-Link Omada Controller up to 5.x. Affected is an unknown function of the component Session Token Handler. Such manipulation leads to insufficiently protected credentials.
This vulnerability is uniquely identified as CVE-2025-9521. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.